The invention discloses a cross-service
network security detection
processing method, which comprises the following steps of: acquiring data from a container during operation, forming a standardized container node behavior
feature vector through context aggregation and vectorization, outputting a behavior deviation degree
score through an
anomaly detection model, identifying suspicious nodes by utilizing a dynamic threshold value, and finally, determining whether the suspicious nodes are abnormal or not. Creating container node situation identification information containing a propagation risk entropy value for the container node; then, on the basis of the service
dependency graph, simulating the propagation process of the risk along the topology, and defining a cross-service
potential risk influence domain; in the domain, performing
gene coding and clustering on node behaviors, and extracting a common
threat behavior mode; and finally, in combination with the tactical matching degree, the influence range and the business criticality, calculating the risk
severity level, thereby completing the whole process from individual
anomaly detection, associated risk propagation to
threat mode grading.